Management device, program, system, apparatus, and method
Abstract
Le dispositif de gestion selon un mode de realisation de la presente invention peut etre connecte a une pluralite d'appareils par l'intermediaired'un reseau. Le dispositif de gestion est muni d'une unite de stockage d'arborescence, une unite de calcul de similarite, une unite d'attribution, et uneunite de transmission d'attribution. L'unite de stockage d'arborescence stocke des informations d'arborescence de gestion dans lesquelles une cle de n*ud est attribuee a un n*ud et un appareil est affecte a un n*ud terminal. L'unite de calcul de similarite calcule la similarite entre des informations d'attribut indiquant l'attribut d'un nouvel appareil et les informations d'attribut d'un appareil deja attribuees dans les informations d'arborescence de gestion. L'unite d'attribution determine, sur la base de la similarite, un n*ud terminal a laquelle le nouvel appareil dans l'arborescence de gestion une information est affectee. L'unite de transmission d'attribution transmet, a ce nouvel appareil, au moins une cle de n*ud associee a un chemin a partir d'un n*ud racine au n*ud terminal correspondant aux informations d'arborescence de gestion.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
20 claims: 11 independent, 9 dependent
- 1複数の機器にネットワークを介して接続可能な管理装置であって、 ノードにノード鍵が割り当てられ、リーフノードに機器が割り当てられた管理木情報を記憶する木記憶部と、 新たな機器の属性を表す属性情報と前記管理木情報に割り当て済みの機器の前記属性情報との類似度を算出する類似度算出部と、 前記類似度に基づき、前記管理木情報における新たな機器を割り当てるリーフノードを決定する割当部と、 新たな機器に、前記管理木情報におけるルートノードから対応するリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信する割当送信部と、 を備える管理装置。
- 2前記割当部は、前記類似度が基準値以上の機器が割り当てられたリーフノードから、予め定められたエッジ数で到達可能な空のリーフノードに、新たな機器を割り当てる 請求項1に記載の管理装置。
- 3前記木記憶部に前記管理木情報が存在していない場合、新たな前記管理木情報を生成して前記木記憶部に記憶させる生成部をさらに備え、 前記割当部は、新たな前記管理木情報の何れかのリーフノードに新たな機器を割り当てる 請求項1または2に記載の管理装置。
- 4前記管理木情報の空のリーフノードの数が予め定められた数より少ない場合、前記管理木情報を拡張する拡張部をさらに備え、 前記割当送信部は、前記管理木情報に割り当て済みの機器に、前記管理木情報におけるルートノードから対応するリーフノードまでのパスに割り当てられたノード鍵のうち、拡張したノードに割り当てられた新たなノード鍵を送信する 請求項1から3の何れか1項に記載の管理装置。
- 5前記割当送信部は、前記管理木情報に割り当て済みの機器に、拡張したノードに割り当てられた新たなノード鍵を、他の機器が保有していない既存のノードに割り当てられていたノード鍵により暗号化して送信する 請求項4に記載の管理装置。
- 6前記拡張部は、前記管理木情報の既存のルートノードの上位層にさらにノードを追加する 請求項4または5に記載の管理装置。
- 7前記拡張部は、前記管理木情報の既存のリーフノードの下位層にさらにノードを追加し、下位層にノードが追加された既存のリーフノードに割り当てられていた機器を、新たなリーフノードに割り当て直す 請求項4または5に記載の管理装置。
- 8前記木記憶部に記憶された前記管理木情報における機器のリーフノードへの割り当て位置を、前記属性情報の前記類似度が予め定められた値以上の機器同士が予め定められたエッジ数で到達可能な範囲に属するように変更する再構成部をさらに備える 請求項1から7の何れか1項に記載の管理装置。
- 9前記属性情報は、それぞれの機器の属性を表す複数の要素情報を含み、 前記類似度算出部は、2つの前記属性情報の前記類似度を算出する場合、対応する前記要素情報を比較し、複数の前記要素情報毎の比較結果を合成して前記類似度を算出する 請求項1から8の何れか1項に記載の管理装置。
- 10前記類似度算出部は、前記要素情報によって比較結果に重みを変えて合成して前記類似度を算出する 請求項9に記載の管理装置。
- 11前記属性情報は、時間によって変化しない前記要素情報と、時間によって変化する前記要素情報とを含む 請求項9または10に記載の管理装置。
- 12複数の機器にネットワークを介して接続可能な管理装置であって、 第1の機器の属性情報である第1属性情報を受け取り、 第1のリーフノードより最も近い第2のリーフノードに割り当てることで構成された木構造のグラフのルートノードから前記第2のリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信し、 前記第1のリーフノードは第2の機器が割り当てられたノードであり、 前記第2の機器は、前記第2の機器の属性情報である第2属性情報が前記第1属性情報と一致する機器である 管理装置。
- 13前記木構造のグラフのルートノードから前記第1のリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を更に送信する 請求項12に記載の管理装置。
- 14複数の機器にネットワークを介して接続可能な管理装置であって、 前記複数の機器の少なくとも1以上の機器の属性情報を受け取り、 木構造のグラフのルートノードから各リーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信し、 前記木構造のグラフは、前記複数の機器のうち、前記受け取った属性情報が一致する機器を第1のリーフノードに割り当てられたものであり、かつ、前記複数の機器のうち、前記受け取った属性情報が一致しない機器を第2のリーフノードに割り当てられたものである 管理装置。
- 15複数の機器にネットワークを介して接続可能な管理装置であって、 第1の機器の識別情報を受け取り、前記第1の機器の識別情報と、1以上の第2の機器の識別情報に基づき構成された木構造のグラフのルートノードからリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信する 管理装置。
- 16複数の機器にネットワークを介して接続可能な管理装置であって、 第1の機器の属性情報を受け取り、前記第1の機器の属性情報と、1以上の第2の機器の属性情報に基づき構成された木構造のグラフのルートノードからリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信する 管理装置。
- 17情報処理装置を、請求項1から16の何れか1項に記載の管理装置として機能させるためのプログラム。
- 18請求項1から16の何れか1項に記載の管理装置と、ネットワークを介して接続可能な複数の機器とを備えるシステム。
- 19請求項18に記載のシステムに備えられる機器であって、 前記属性情報を前記管理装置へと送信する属性送信部を有する機器。
- 20複数の機器にネットワークを介して接続可能な管理装置において実行される方法であって、 前記管理装置は、ノードにノード鍵が割り当てられ、リーフノードに機器が割り当てられた管理木情報を記憶する木記憶部を備え、 前記管理装置は、 新たな機器の属性を表す属性情報と前記管理木情報に割り当て済みの機器の前記属性情報との類似度を算出し、 前記類似度に基づき、前記管理木情報における前記新たな機器を割り当てるリーフノードを決定し、 前記新たな機器に、前記管理木情報におけるルートノードから対応するリーフノードまでのパスに割り当てられた少なくとも1つのノード鍵を送信する 方法。
Independent claims20
171 paragraphs, as filed
A controlling device, a program, a system, apparatus, and a method
0001The embodiment of the present invention is related with a controlling device, a program, a system, apparatus, and a method.
0002The key which some apparatus of a plurality of apparatus shares and holds is called a group key. By enciphering data using such a group key, data can be transmitted to the apparatus belonging to a group, and data can be kept secret to the apparatus which does not belong to a group. It is a key for distributing a group key to each apparatus, and calls a device key the key distributed to each apparatus.
0003The method of managing a device key using the management tree information which is data showing the graph of a tree structure is known. In this method, a node key is assigned to each node in management tree information, and apparatus is assigned to a leaf node. In this method, all the node keys assigned to the path to the leaf node corresponding to each apparatus from a route node are distributed. And in this method, apparatus memorizes the group of all the distributed node keys as a device key. At the time of distribution, a group key is enciphered with any one or more node keys contained in a device key.
0004By the way, when new apparatus is connected into a system, the controlling device which manages management tree information must distribute a node key and a group key to new apparatus. In this case, the controlling device must assign new apparatus to management tree information so that information can be efficiently transmitted to a plurality of apparatus belonging to the same group.
<p num="0005"><patcit num="1"><text>JP, 2012-204897, A</text></patcit></p>
<p num="0006">There is the issue which the present invention tends to solve in assigning apparatus to management tree information so that information can be efficiently transmitted to a plurality of apparatus.</p>
<p num="0007">The controlling device concerning an embodiment is a connectable controlling device via a network at a plurality of apparatus. The above-mentioned controlling device is provided with a tree storage part, a similarity calculating part, a quota part, and a quota transmission section. The above-mentioned tree storage part memorizes the management tree information that the node key was assigned to the node and apparatus was assigned to the leaf node. The above-mentioned similarity calculating part is assigned to the attribute information and the above-mentioned management tree information that the attribute of new apparatus is expressed, and computes the degree of similar with the above-mentioned attribute information on the apparatus of ending. The above-mentioned quota part determines the leaf node which assigns the above-mentioned new apparatus in the above-mentioned management tree information based on the above-mentioned degree of similar. The above-mentioned quota transmission section transmits at least one node key assigned to the path to a leaf node which is equivalent to the above-mentioned new apparatus from the route node in the above-mentioned management tree information.</p>
0008<figref num="1">The lineblock diagram of the communications system concerning an embodiment.</figref><figref num="2">The figure showing an example of management tree information.</figref><figref num="3">The figure showing an example of a group.</figref><figref num="4">The figure showing the attribute information transmitted to a controlling device from apparatus.</figref><figref num="5">The figure showing the transmitting example of the node key determined based on attribute information.</figref><figref num="6">The figure showing the composition of a controlling device.</figref><figref num="7">The figure showing the calibration of apparatus.</figref><figref num="8">The figure showing the element contained in attribute information.</figref><figref num="9">The sequence figure of the communications system concerning an embodiment.</figref><figref num="10">The flow chart of quota processing of a controlling device.</figref><figref num="11">The flow chart in Step S25 of Drawing 10 which shows an example of processing.</figref><figref num="12">The figure showing the 1st example of quota.</figref><figref num="13">The figure showing the 2nd example of quota.</figref><figref num="14">The figure showing the 1st example of the management tree information before extension.</figref><figref num="15">The figure showing the example which extended the higher rank layer.</figref><figref num="16">The figure showing the 2nd example of the management tree information before extension.</figref><figref num="17">The figure showing the example which extended the lower layer.</figref><figref num="18">The figure showing the example which extended the middle class.</figref><figref num="19">The figure showing the example which extended the lower layer of one leaf node.</figref><figref num="20">The figure showing the example which extended the layer between one leaf node and a route node.</figref><figref num="21">The figure showing the management tree information before reconstruction.</figref><figref num="22">The figure showing the management tree information after reconstruction.</figref><figref num="23">The figure showing the hardware constitutions of a controlling device.</figref>
0009Hereinafter, the communications system concerning an embodiment is explained in detail, referring to drawings. The transmission systems concerning this embodiment can assign apparatus to management tree information so that the information on a group key etc. can be efficiently transmitted to a plurality of apparatus.
0010The encryption key which enciphers data is used in this embodiment. Symmetrical key code methods, such as AES, may be used for the algorithm for enciphering and decoding data with an encryption key, and an asymmetrical key code method (public-key crypto system) may be used for it.
0011Drawing 1 is a figure showing the composition of communications system 10 concerning an embodiment. Communications system 10 is provided with controlling device 20 and a plurality of apparatus 30 (30-A - 30-F).
0012Controlling device 20 and a plurality of apparatus 30 of each other are connectable via a network. A network is LAN etc. which were formed, for example in the home. In a network, public lines, such as the Internet or VPN (Virtual Private Network), may be contained. The network can apply various forms, such as wireless LAN based on IEEE802.11, Ethernet (registered trademark), and IEEE1394, as a physical layer and a link layer.
0013Controlling devices 20 are information processors, such as a computer. On the operating system, controlling device 20 ran the predetermined program, for example, has always started it.
0014Apparatus 30 is a device which has a communication function and an information processing function. For example, apparatus 30 may be electric appliances (it is an air-conditioner, a TV apparatus, a refrigerator, etc., and is a device connectable with a network) used at home. Apparatus 30 may be portable information machines and equipment, such as a smart phone, a tablet, or a note type computer.
0015In communications system 10, data is transmitted between controlling device 20 and apparatus 30 or between apparatus 30 and apparatus 30. The data transmitted is the discernment information on the value of the key which the control commands, controlling device 20, or apparatus 30 for controlling operation of apparatus 30 uses for encryption or attestation, for example, the identifier information on a key and controlling device 20, or apparatus 30, including a MAC Address or an IP address, etc. The data transmitted may be video data, voice data, text data, or a program code.
0016Such data is enciphered with a group key. A group key is a key which apparatus 30 belonging to a group holds in common.
0017Controlling device 20 sets up a group in accordance with a user's etc. directions or the rule set up beforehand as opposed to a plurality of apparatus 30 connected to the network. Controlling device 20 may set up a plurality of groups. Controlling device 20 may make one apparatus 30 belong to a plurality of groups. Apparatus 30 which does not belong to a group may exist. Controlling device 20 assigns a peculiar group key for every group. By enciphering data with a group key and transmitting to a network, controlling device 20 can make apparatus 30 belonging to a group able to acquire data, and can keep data secret to apparatus 30 which does not belong to a group.
0018It enciphers with the node key to which the group key was assigned by each apparatus 30, and gives controlling device 20 to apparatus 30. A node key is a key which controlling device 20 and apparatus 30 share. One apparatus 30 holds the group of at least one node key as a device key. Controlling device 20 manages the node key which each apparatus 30 holds using the management tree information to express for a tree structure (undirected graph which does not have a loop). Controlling device 20 may encipher data with a node key, and may transmit to apparatus 30.
0019Drawing 2 is a figure showing an example of management tree information. Management tree information contains a plurality of edge which connects between a plurality of nodes (with a circle [of Drawing 2] shows), and nodes and nodes. One node of the peak (the top layer) of a tree structure is called a route node. Each node arranged at the end (the lowest layer) of a tree structure is called a leaf node.
0020The peculiar node number is assigned to the node. In the example of Drawing 2, the number in a circle shows a node number.
0021Controlling device 20 assigns a node key to each node. Node keys differ for every node. In the example of Drawing 2, as for controlling device 20, the node number is assigning the node key of K1-K15 to the node of 1-15.
0022Controlling device 20 assigns each apparatus 30 to which leaf node. Controlling device 20 assigns one apparatus 30 to one leaf node, and does not overlap and assign a plurality of apparatus 30 to one leaf node. Management tree information may contain the leaf node of the sky where neither of the apparatus 30 is assigned. In the example of Drawing 2, controlling device 20 is assigning apparatus 30 of discernment information A, B, and C, D, E, and F to the node of node numbers 8, 9, 10, 11, 13, and 15.
0023From a route node [in / to each apparatus 30 / in controlling device 20 / management tree information], At least one node key (for example, all the node keys currently assigned to the path corresponding from a route node to a leaf node) currently assigned to the corresponding path to a leaf node to which the apparatus 30 concerned was assigned is transmitted. Apparatus 30 memorizes the group of at least one node key transmitted from controlling device 20 as a device key. For example, controlling device 20 transmits the node key of K1, K2, K4, and K8 to apparatus 30 of discernment information A assigned to node number 8. Controlling device 20 needs to transmit no node keys to a path to a leaf node corresponding from a route node, if the node key assigned to the leaf node at least is transmitted.
0024Management tree information may be not only more than a binary tree but a 3-minute tree. Management tree information may be a tree structure of non-completeness, and may be various structures.
0025Drawing 3 is a figure showing an example of a group. Controlling device 20 generates a peculiar group key for every group. Controlling device 20 transmits at least one cryptogram which enciphered and generated one group key with at least one node key to each apparatus 30 belonging to a group. Specifically, controlling device 20 chooses at least one node key so that the number of the cryptograms which all the apparatus 30 belonging to a group can decode which cryptogram, and transmit may decrease most. And with each selected node key, controlling device 20 generates a cryptogram and transmits.
0026In the example of Drawing 3, apparatus 30 of discernment information A and B forms group alpha. Node key K4 does not hold other apparatus 30, although apparatus 30 of discernment information A and B holds in common. Therefore, controlling device 20 enciphers group key GKalpha of group alpha with node key K4. Thereby, controlling device 20 can transmit group key GKalpha to two apparatus 30 which forms group alpha efficiently.
0027In the example of Drawing 3, discernment information A, B, and C and apparatus 30 of D form group beta. Node key K2 does not hold other apparatus 30, although discernment information A, B, and C and apparatus 30 of D hold in common. Therefore, controlling device 20 enciphers group key GKbeta of group beta with node key K2. Thereby, controlling device 20 can transmit group key GKbeta to four apparatus 30 which forms group beta efficiently.
0028In the example of Drawing 3, apparatus 30 of discernment information E and F forms group gamma. Node key K3 does not hold other apparatus 30, although apparatus 30 of discernment information E and F holds in common. Therefore, controlling device 20 enciphers group key GKgamma of group gamma with node key K3. Thereby, controlling device 20 can transmit group key GKgamma to two apparatus 30 which forms group gamma efficiently.
0029Drawing 4 is a figure showing the node key determined based on the attribute information transmitted to apparatus 30 from the attribute information transmitted to controlling device 20, and controlling device 20 from apparatus 30. Drawing 5 is a figure showing other transmitting examples of the node key determined based on attribute information and attribute information.
0030Apparatus 30 transmits the attribute information showing the attribute of the apparatus 30 concerned to controlling device 20. Attribute information includes at least one element information. Attribute information includes discernment information, a vendor name, classification, average consumption electric power, or a most frequent command name as element information, for example. The details of attribute information are mentioned below with reference to Drawing 8.
0031Controlling device 20 determines one or more node keys assigned to each apparatus 30 based on such attribute information, and transmits the node key to apparatus 30. As shown in Drawing 5, controlling device 20 transmits the node key after changing into apparatus 30-2, when change arises in assignment of the node key of other apparatus 30-2 with assignment of the node key to apparatus 30-1.
0032Here, controlling device 20 receives the attribute information on the 1st apparatus 30, and transmits at least one node key assigned to the path from the route node of the management tree information constituted based on the attribute information on the 1st apparatus 30, and the attribute information on the 2nd one or more apparatus 30 to a leaf node.
0033More specifically, controlling device 20 receives the 1st attribute information which is attribute information on the 1st apparatus 30, At least one node key assigned to the path from the route node of the management tree information which comprised the 1st leaf node by assigning the 2nd nearest leaf node to the 2nd leaf node is transmitted. The 1st leaf node is a node to which the 2nd apparatus 30 was assigned. The 2nd apparatus 30 is apparatus 30 whose 2nd attribute information which is attribute information on the 2nd apparatus 30 corresponds with the 1st attribute information. Controlling device 20 may further transmit at least one node key assigned to the path from the route node of management tree information to the 1st leaf node in this case.
0034Controlling device 20 may receive the attribute information on at least one or more apparatus 30 of a plurality of apparatus 30, and may transmit at least one node key assigned to the path from the route node of management tree information to each leaf node. In this case, management tree information is assigned apparatus 30 whose attribute information which apparatus 30 whose attribute information received among a plurality of apparatus 30 corresponds was assigned by the 1st leaf node, and was received among a plurality of apparatus 30 does not correspond by the 2nd leaf node.
0035For example, controlling device 20 determines a quota position (position of a leaf node) based on the attribute information on the new apparatus 30, when assigning new apparatus 30 to management tree information. More specifically, controlling device 20 determines the quota position of new apparatus 30 so that apparatus 30 comrades of similar attribute information may become near and apparatus 30 comrades of the attribute information which is not similar may become far. Thereby, controlling device 20 can transmit the information on a group key etc. to a plurality of apparatus 30 belonging to the same group efficiently for the small amount of information (the number of cryptograms).
0036Drawing 6 is a figure showing the composition of controlling device 20. Controlling device 20 is with tree storage part 41, group storage part 42, and attribute storage part 43, It has apparatus finding part 44, apparatus authentication section 45, attribute acquiring part 46, similarity calculating part 47, quota part 48, quota transmission section 49, group key transmission section 50, generation part 51, extended part 52, reconstruction section 53, encryption section 54, and the 1st communications department 55.
0037Tree storage part 41 memorizes the management tree information that the node key was assigned to the node and apparatus 30 was assigned to the leaf node. Group storage part 42 memorizes group discernment information, a group key, and the list of apparatus 30 that belongs for every group. Attribute storage part 43 memorizes attribute information every apparatus 30.
0038Apparatus finding part 44 discovers apparatus 30 which exists on a network. Apparatus authentication section 45 performs attestation processing with apparatus 30, and checks whether it has authority with a communication partner's just apparatus 30.
0039Attribute acquiring part 46 acquires attribute information from attested apparatus 30. Attribute acquiring part 46 acquires attribute information from new apparatus 30, when new apparatus 30 is connected to a network, for example. Attribute acquiring part 46 may acquire periodically the element information which changes with time among attribute information from each apparatus 30. Attribute acquiring part 46 makes attribute storage part 43 memorize the acquired attribute information.
0040Similarity calculating part 47 computes the degree of similar of the attribute information on two apparatus 30. For example, in connecting new apparatus 30 to a network and assigning the new apparatus 30 to management tree information, similarity calculating part 47 is assigned to the attribute information and management tree information on new apparatus 30, and computes the degree of similar with the attribute information on each apparatus 30 of ending.
0041Quota part 48 assigns new apparatus 30 to the management tree information memorized by tree storage part 41. In this case, quota part 48 is assigned to the attribute information and management tree information on new apparatus 30, and determines the quota position (position of a leaf node) of new apparatus 30 based on the degree of similar with the attribute information on existing apparatus 30 of ending. More specifically, quota part 48 determines the position of the leaf node which assigns new apparatus 30 so that apparatus 30 comrades with the high degree of similar may be arranged at the near range. For example, quota part 48 assigns new apparatus 30 to the leaf node of the empty which can reach with the number of edge defined beforehand from the leaf node to which apparatus 30 (for example, apparatus 30 with the highest degree of similar) whose degree of similar with the attribute information on new apparatus 30 is higher than a standard was assigned.
0042When new apparatus 30 is assigned to management tree information, quota transmission section 49 enciphers at least one node key with the key shared by attestation processing, and transmits to new apparatus 30. More specifically, quota transmission section 49 transmits at least one node key assigned to the path from the route node in management tree information to the leaf node corresponding to new apparatus 30 to new apparatus 30. New apparatus 30 memorizes the group of at least one received node key as a device key. Quota transmission section 49 may encipher the discernment information on the quota position in management tree information, and a node key to new apparatus 30, and may transmit to it.
0043Group key transmission section 50 generates a group key, when a new group is formed. And group key transmission section 50 transmits a group key to all the apparatus 30 belonging to the formed new group. In this case, all the apparatus 30 in which group key transmission section 50 belongs to a group holds any at least one. 1 or a plurality of node keys where whose number of cryptograms apparatus 30 which does not belong to a group does not hold, and decreases most are chosen. And group key transmission section 50 enciphers a group key with 1 selected or a plurality of node keys, and transmits 1 or a plurality of cryptograms.
0044Group key transmission section 50 transmits the group key corresponding to new apparatus 30, when new apparatus 30 is assigned to management tree information and the new apparatus 30 is added to which group. In this case, new apparatus 30 holds group key transmission section 50. A corresponding group key is enciphered with a node key which apparatus 30 which does not belong to a group does not hold.
0045Generation part 51 generates new management tree information, and it makes tree storage part 41 memorize it. For example, new apparatus 30 is first connected to a network, and when the management information which should be assigned does not exist in tree storage part 41, generation part 51 generates new management tree information, and it makes tree storage part 41 memorize it.
0046Extended part 52 extends the management tree information memorized by tree storage part 41, when there are few leaf nodes of the empty of management tree information than the number defined beforehand. For example, extended part 52 is a case where new apparatus 30 is connected to a network, and when an empty leaf node does not exist in the management tree information memorized by tree storage part 41, it extends management tree information. It says adding a new node and edge so that the leaf node by which extending management tree information is included in management tree information may increase.
0047Reconstruction section 53 reconstructs the management tree information memorized by tree storage part 41. For example, reconstruction section 53 changes the quota position to the leaf node of apparatus 30 in management tree information so that apparatus 30 comrades with the high degree of similar may concentrate on the near range and may be arranged. More specifically, reconstruction section 53 is changed, for example so that apparatus 30 comrades beyond the value as which the quota position to the leaf node of apparatus 30 in management tree information was beforehand determined to the degree of similar of attribute information may belong to the range which can reach with the number of edge defined beforehand. Reconstruction section 53 performs reconstruction, when the event defined periodically or beforehand occurs for example.
0048Encryption section 54 enciphers the target data using a group key or a node key, when transmitting data to which apparatus 30 from controlling device 20. Encryption section 54 enciphers the target data with a group key, when bundling up to apparatus 30 belonging to the specified group and transmitting data. When transmitting data to any one or a plurality of apparatus 30 which were specified, specified apparatus 30 holds encryption section 54. A node key which other apparatus 30 does not hold is chosen, and the target data is enciphered.
0049The 1st communications department 55 communicates with apparatus 30 via a network. The 1st communications department 55 performs layer processing of the physical layer for communicating with apparatus 30, a data link layer, etc., for example.
0050Drawing 7 is a figure showing the calibration of apparatus 30. Apparatus 30 has information storage part 61, fixed attribute storage part 62, attribute measurement part 63, controlling device finding part 64, demand part 65, controlling device authentication section 66, attribute transmission section 67, quota receiving part 68, group key receiving part 69, decoding part 70, and the 2nd communications department 71.
0051Information storage part 61 memorizes the device key which is a group of at least one node key assigned to this apparatus 30. Information storage part 61 may memorize the quota position in the discernment information and management tree information on each node key. Information storage part 61 memorizes the group key of a group and the discernment information on a group that this apparatus 30 belongs.
0052Fixed attribute storage part 62 memorizes the element information which does not change with time among the element information included in attribute information. Attribute measurement part 63 measures the element information which changes with time among the element information included in attribute information. Attribute measurement part 63 may be measured periodically, and when the event defined beforehand occurs, it may be measured.
0053Controlling device finding part 64 discovers controlling device 20 which exists on a network. Demand part 65 requires assignment to management tree information, and issue of the group of at least one node key from controlling device 20. Demand part 65 requires issue of the group of at least one node key, when this apparatus 30 is newly connected to a network, for example. Controlling device authentication section 66 performs attestation processing with controlling device 20, and checks whether it has authority with a communication partner's just controlling device 20.
0054Attribute transmission section 67 transmits attribute information to controlling device 20. At the time of assignment to management tree information, and the demand of issue of the group of at least one node key, attribute transmission section 67 transmits attribute information to controlling device 20, for example. Attribute transmission section 67 may transmit the element information of the element information included in attribute information which carries out time change to controlling device 20, when the event which was able to be defined periodically or beforehand occurs.
0055Quota receiving part 68 receives at least one node key transmitted from controlling device 20. Quota receiving part 68 makes information storage part 61 memorize the group of at least one received node key as a device key. Quota receiving part 68 receives the quota position in the management tree information on this apparatus 30, and the discernment information on each node key. Quota receiving part 68 makes information storage part 61 memorize these pieces of received information. When this apparatus 30 is newly connected to a network, the discernment information on a node key, a quota position, and a node key is enciphered with the key shared by attestation processing between controlling devices 20. Quota receiving part 68 decodes the discernment information on a node key, a quota position, and a node key with this shared key.
0056Group key receiving part 69 receives the group key enciphered from controlling device 20. The group key is enciphered with which node key of the groups of at least one node key contained in the device key which this apparatus 30 holds. Therefore, group key receiving part 69 chooses which node key of the groups of at least one node key contained in the device key memorized by information storage part 61, and decodes a group key using the selected node key. Group key receiving part 69 makes information storage part 61 memorize the decoded group key.
0057Decoding part 70 decodes the data transmitted from controlling device 20 using a group key or which node key contained in a device key. The 2nd communications department 71 communicates with controlling device 20 and other apparatus 30 via a network. The 2nd communications department 71 performs layer processing of the physical layer for communicating with controlling device 20 or other apparatus 30, a data link layer, etc., for example.
0058Drawing 8 is a figure showing the element contained in attribute information. Attribute information includes the element information (fixed element information) which does not change with time, and the element information (element information on a variation per hour) which changes with time. Attribute information may also include either of fixed element information and the element information on a variation per hour.
0059Fixed element information is discernment information, a vendor name, classification, the amount of memories, maximum electric power consumption, etc. as an example. Discernment information is information for identifying apparatus 30 uniquely on a network. For example, it is a MAC Address, an IP address, or a serial number of apparatus 30, etc. A vendor name is a manufacture company name or a sales company name of apparatus 30, etc. Classification is a name showing the product function of apparatus 30. Specifically, as for classification, an air-conditioner, a TV apparatus, a refrigerator, etc. are described, for example.
0060The amount of memories is a capacity value of the memory with which apparatus 30 is provided. The amounts of memories may be information, including whether not only a capacity value but a capacity value is larger than the threshold defined beforehand. Maximum electric power consumption is the maximum of the electric power which apparatus 30 consumes.
0061The element information on a variation per hour is average consumption electric power, a most frequent command name, command frequency, etc. as an example. Average consumption electric power is the average value of the electric power which apparatus 30 consumed in a certain period (from commencement of commercial operation up to this time). A most frequent command name is a name of most control commands which apparatus 30 executed in a certain period (from commencement of commercial operation up to this time). Command frequency is frequency in which apparatus 30 executed control commands in a certain period (from commencement of commercial operation to this time).
0062The element information included in attribute information is a model name, for example in addition to these, The amount of cash of apparatus, the name of CPU (Central Processing Unit), They may be rated power consumption, a communication method, network topology, the number of hop until it reaches apparatus 30 from controlling device 20, electric wave intensity, the date of manufacture of apparatus 30, a setting position of apparatus 30, the discernment information on the peripheral equipment which apparatus 30 can move, is fixation, or is connected, etc. What kind of combination may the combination of the element information included in attribute information be?
0063Drawing 9 is a sequence figure of communications system 10 concerning an embodiment. In communications system 10, when new apparatus 30 is connected to a network, processing is performed according to the sequence shown in Drawing 9.
0064First, in Step S11, controlling device 20 and apparatus 30 discover mutual apparatus via a network. Then, in Step S12, apparatus 30 requires assignment to management tree information, and issue of the group (device key) of at least one node key from controlling device 20.
0065Then, in Step S13, controlling device 20 and apparatus 30 perform attestation processing mutually, and check whether a communication partner has just authority. The attestation processing for judging whether I may connect with apparatus 30 of Step S13 may be combined with processing of Step S11 or Step S12, and controlling device 20 may perform it.
0066Controlling device 20 and apparatus 30 are attested using the method of ISO/IEC 9798-1 or ISO/IEC9798-3 grade, for example. Controlling device 20 and apparatus 30 may be attested by the method of using a public key certificate. Controlling device 20 and apparatus 30 may generate the key used for attestation based on the password shared beforehand, and the secret key embedded by apparatus 30 in the lock used for attestation at the time of factory shipments, etc. may be used for them.
0067Then, when a partner checks that it is just controlling device 20, in Step S14, apparatus 30 transmits attribute information. In this case, apparatus 30 transmits the element information which does not carry out time change. Apparatus 30 may also transmit the element information which carries out time change, case [whose element information which carries out time change has been measured].
0068As long as apparatus 30 is before the next quota processing (S15), it may transmit attribute information any time. For example, apparatus 30 may transmit to one entry of a device description including attribute information, when using UPnP SSDP for discovery processing (S11). When apparatus 30 uses HTTP for the protocol of demand processing (S12), The field for exclusive use may be defined as one entity of a HTTP request header, attribute information may be transmitted, and the storing place of attribute information may be included in URL of a HTTP GET request.
0069Then, in Step S15, controlling device 20 performs quota processing which assigns apparatus 30 to which leaf node in management tree information. Quota processing is mentioned below with reference to Drawing 10.
0070Then, in Step S16, controlling device 20 transmits the quota information acquired by quota processing of Step S15 to apparatus 30. Quota information contains the group (device key) of at least one node key assigned to corresponding apparatus 30. Quota information may also include the quota position in management tree information, and the discernment information on each node key. Controlling device 20 enciphers quota information with the key shared by attestation processing, and transmits to apparatus 30.
0071Then, in Step S17, controlling device 20 acquires the group key of a group with which corresponding apparatus 30 belongs, and enciphers it or more by node any 1 of at least one node keys which transmitted to apparatus 30 at Step S16. In this case, controlling device 20 enciphers a group key with the node key which apparatus 30 other than a group does not hold.
0072Then, in Step S18, the enciphered group key is transmitted to apparatus 30. Then, in Step S19, apparatus 30 receives the group key enciphered from controlling device 20, chooses which node key of the groups (device key) of at least one held node key, and decodes it with the selected node key. By the above processing, apparatus 30 can acquire the group (device key) of at least one node key, and a group key from controlling device 20.
0073Drawing 10 is a flow chart of quota processing of controlling device 20. Controlling device 20 performs processing shown in Drawing 10 in quota processing (S15).
0074First, in Step S21, generation part 51 of controlling device 20 judges whether management tree information exists in tree storage part 41. When management tree information does not exist (No of S21), generation part 51 generates new management tree information, and it makes tree storage part 41 memorize it in Step S22. In this case, generation part 51 generates the management tree information on i stage that the hierarchy was defined beforehand (i is an integer greater than or equal to 2). The hierarchy of management tree information expresses the number of edge of the route from a route node to a leaf node. Then, in Step S23, quota part 48 of controlling device 20 assigns new apparatus 30 to which leaf node in new management tree information. And after ending Step S23, controlling device 20 ends quota processing.
0075On the other hand, when management tree information exists (Yes of S21), in Step S24, similarity calculating part 47 of controlling device 20 computes the degree of similar of the new attribute information on apparatus 30, and the attribute information on each apparatus 30 already assigned to management tree information.
0076When computing the degree of similar of two attribute information, similarity calculating part 47 compares whether corresponding element information is the same or the difference of a value is in a fixed range, for example. For example, or [that similarity calculating part 47 has the same vendor name, or its classification is the same], The difference of the amount of memories is in a fixed range, the difference of maximum electric power consumption is in a fixed range, the difference of average consumption electric power is in a fixed range, or it is compared whether a most frequent command name is the same or the difference of command frequency is in a fixed range.
0077And similarity calculating part 47 computes the degree of similar by compounding the comparison result for every element information of a plurality of. For example, similarity calculating part 47 does not have one point and the same element information, when element information is the same or the difference of a value is in a fixed range, or when the difference of the value has exceeded the fixed range, it considers it as zero point, and it makes the value which totaled the mark of a plurality of element information the degree of similar.
0078Similarity calculating part 47 may compare about not all the element information of the attribute information, but may extract and compare specific 1 or a plurality of element information which were defined beforehand. For example, it may compute the degree of similar by similarity calculating part 47 measuring classification and average consumption electric power, and compounding these comparison results.
0079Similarity calculating part 47 may change and compound dignity to a comparison result using element information. Similarity calculating part 47 may change dignity, as it was called four points, when it was within the limits in which the difference of the value of two points and average consumption electric power is constant when classification is in agreement and five points and a vendor name are in agreement for example. Similarity calculating part 47 may be replaced with the above calculating method, and may compute the degree of similar with other calculating methods.
0080Then, in Step S25, quota part 48 assigns new apparatus 30 to which leaf node in management tree information based on the computed degree of similar. In this case, quota part 48 assigns new apparatus 30 to the leaf node of which empty so that similar apparatus 30 may focus close and may be arranged. For example, quota part 48 assigns new apparatus 30 to the leaf node of the empty which can reach within the fixed number of edge from the attribute information on new apparatus 30, and apparatus 30 with the highest degree of similar. When the leaf node of the empty which can reach within the fixed number of edge from apparatus 30 with the highest degree of similar does not exist, quota part 48 may assign new apparatus 30, after making management tree information extend to extended part 52.
0081And after ending Step S25, controlling device 20 ends quota processing.
0082Drawing 11 is a flow chart in Step S25 of Drawing 10 which shows an example of processing. Quota part 48 may perform processing as shown in Drawing 11 in Step S25 of Drawing 10.
0083First, in Step S31, quota part 48 detects the leaf node to which apparatus 30 with the highest degree of similar with the attribute information on new apparatus 30 among apparatus 30 already assigned to management tree information was assigned.
0084Then, in Step S32, quota part 48 judges whether an empty leaf node exists within n degree of kinship from the leaf node to which apparatus 30 with the highest degree of similar was assigned. here, as for the leaf nodes within n degree of kinship, (n is one or more integers.) -- other leaf nodes which can reach with n times or less of the numbers of edge are said from the leaf node to which a certain apparatus 30 was assigned. For example, in the example shown in Drawing 2, the number of the degree of kinship between leaf node 8 and leaf node 9 is 2. The number of the degree of kinship between leaf node 8 and leaf node 12 is 6.
0085When an empty leaf node exists within n degree of kinship from the leaf node to which apparatus 30 with the highest degree of similar was assigned (Yes of S32), in Step S33, quota part 48 assigns new apparatus 30 to the leaf node of the empty within the n degree of kinship. That is, quota part 48 assigns new apparatus 30 to the leaf node of the empty which can reach with the number of edge defined beforehand from the leaf node to which apparatus 30 with the highest degree of similar was assigned. Thereby, quota part 48 can assign new apparatus 30 to a position with the attribute information near most similar existing apparatus 30 in management tree information.
0086In Step S31, quota part 48 may detect the leaf node to which apparatus 30 whose degree of similar of beyond a standard value is [the degree of similar] the highest was assigned. In this case, new apparatus 30 may be assigned to the leaf node of the sky where the degree of similar separated quota part 48 from n degree of kinship conversely if apparatus 30 beyond a standard value did not exist. Thereby, quota part 48 can assign new apparatus 30 to the long distance position of existing apparatus 30 by which the attribute information in management tree information is not similar.
0087And controlling device 20 returns processing to the flow of Drawing 10, after ending Step S33.
0088When an empty leaf node does not exist within n degree of kinship from the leaf node to which apparatus 30 with the highest degree of similar was assigned on the other hand (No of S32), in Step S34, quota part 48 judges whether an empty leaf node exists in management tree information. Quota part 48 advances processing to Step S35, when an empty leaf node does not exist in management tree information (No of S34), and when an empty leaf node exists in management tree information (Yes of S34), it advances processing to Step S36.
0089In Step S35, extended part 52 extends the tree structure of management tree information. Thereby, extended part 52 can create an empty leaf node to management tree information. And after extended part 52 extends management tree information, it returns processing to Step S32, and makes processing repeat. Extended part 52 may advance processing to Step S36, after extending management tree information. Extended processing of management tree information is mentioned below with reference to Drawing 14 - Drawing 20.
0090In Step S36, quota part 48 assigns new apparatus 30 to the leaf node of which empty. And controlling device 20 returns processing to the flow of Drawing 10, after ending Step S36.
0091In Step S34, quota part 48 may judge whether it replaces with whether an empty leaf node exists in management tree information, and more than the number with which the empty leaf node was beforehand provided in management tree information exists. In this case, if, as for quota part 48, more than the number with which the empty leaf node was defined beforehand does not exist, processing is advanced to Step S35, and if it exists, it will advance processing to Step S36.
0092Drawing 12 is a figure showing the 1st example of quota of apparatus 30 to management tree information. For example, management tree information is the structure of a perfect binary tree of two hierarchies, as shown in Drawing 12. It is assumed that 1st apparatus 30-A is assigned to a leaf node of node number 4, 2nd apparatus 30-B is assigned to a leaf node of node number 6, and 3rd apparatus 30-C is assigned to a leaf node of node number 7. In the example of Drawing 12, 1st apparatus 30-A holds the group (device key) of three node keys K1, K2, and K4.2nd apparatus 30-B holds the group (device key) of three node keys K1, K3, and K6.3rd apparatus 30-C holds the group (device key) of three node keys K1, K3, and K7.
0093In the example of Drawing 12, when making 1st apparatus 30-A and 2nd apparatus 30-B execute control commands CMD, controlling device 20 generates two cryptograms denoted by a following formula, and transmits. Thereby, 1st apparatus 30-A and 2nd apparatus 30-B can hold group key GK. E (K, M) expresses the cryptogram which enciphered data M using key K. C1=E (K4, GK) C2=E (K6, GK)
0094Then, controlling device 20 enciphers control commands CMD as being expressed with a following formula using group key GK, and carries out multicasting transmission of the cryptogram. C3=E (GK, CMD)
00951st apparatus 30-A and 2nd apparatus 30-B decode the received cryptogram using group key GK. Thereby, 1st apparatus 30-A and 2nd apparatus 30-B can execute control commands CMD. Thus, as shown management tree information in Drawing 12, when it is constituted, controlling device 20 can make 1st apparatus 30-A and 2nd apparatus 30-B execute control commands CMD by transmitting three cryptograms.
0096Controlling device 20 can also make 1st apparatus 30-A and 2nd apparatus 30-B execute control commands CMD in the example of Drawing 12, without transmitting group key GK. In this case, controlling device 20 generates the cryptogram denoted by a following formula, and transmits. When not transmitting group key GK, controlling device 20 can make 1st apparatus 30-A and 2nd apparatus 30-B execute control commands CMD by transmitting two cryptograms. C1'=E (K4, CMD) C2'=E (K6, CMD)
0097Drawing 13 is a figure showing the 2nd example of quota of apparatus 30 to management tree information. In the point that 2nd apparatus 30-B is assigned to the node of node number 5, the management tree information shown in Drawing 13 differs from Drawing 12. In the example of Drawing 13, 2nd apparatus 30-B holds the group (device key) of three node keys K1 and K2 and K5.
0098In the example of Drawing 13, in order to make 1st apparatus 30-A and 2nd apparatus 30-B execute control commands CMD, first, controlling device 20 generates the cryptogram denoted by a following formula, and carries out multicasting transmission. Thereby, 1st apparatus 30-A and 2nd apparatus 30-B can hold group key GK. C1''=E (K2, GK)
0099Then, controlling device 20 enciphers control commands CMD as being expressed with a following formula using group key GK, and carries out multicasting transmission of the cryptogram. C3=E (GK, CMD)
01001st apparatus 30-A and 2nd apparatus 30-B decode the received cryptogram using group key GK. Thereby, 1st apparatus 30-A and 2nd apparatus 30-B can execute control commands CMD. As mentioned above, as shown management tree information in Drawing 13, when it is constituted, controlling device 20 can make 1st apparatus 30-A and 2nd apparatus 30-B execute control commands CMD by transmitting two cryptograms.
0101Controlling device 20 can also make 1st apparatus 30-A and 2nd apparatus 30-B execute control commands CMD in the example of Drawing 13, without transmitting group key GK. In this case, controlling device 20 generates the cryptogram denoted by a following formula, and carries out multicasting transmission. Thus, when not transmitting group key GK, controlling device 20 can make 1st apparatus 30-A and 2nd apparatus 30-B execute control commands CMD by transmitting one cryptogram. C1'''=E (K2, CMD)
0102As mentioned above, when making 1st apparatus 30-A and 2nd apparatus 30-B execute the same control commands CMD, the direction of the management tree information on Drawing 13 can lessen the amount of transmission of data, and it is more efficient than the management tree information on Drawing 12.
0103Here, the management tree information on Drawing 12 is compared with the management tree information on Drawing 13. As for the management tree information on Drawing 12, between the leaf node to which 1st apparatus 30-A was assigned, and the leaf nodes to which 2nd apparatus 30-B was assigned serves as distance of the relation in the 4th degree. On the other hand, as for the management tree information on Drawing 13, between the leaf node to which 1st apparatus 30-A was assigned, and the leaf nodes to which 2nd apparatus 30-B was assigned serves as distance of the relation in the 2nd degree. That is, 1st apparatus 30-A and 2nd apparatus 30-B are assigned to the range in which the management tree information on Drawing 13 is nearer than the management tree information on Drawing 12. From this, the management tree information can make the amount of information (the number of cryptograms) which transmits less than the case where apparatus 30 comrades belonging to one group are assigned to the leaf node it is further to assign to the near leaf node.
0104Controlling device 20 has a high possibility of transmitting the same data to a plurality of apparatus 30 with the high degree of similar of attribute information simultaneously. For example, when controlling the power consumption of the whole communications system 10, controlling device 20 has a high possibility of transmitting simultaneously the control commands etc. to which power consumption is reduced to a plurality of air-conditioners. Therefore, controlling device 20 can lessen the amount of information (the number of cryptograms) which transmits by assigning a plurality of apparatus 30 with the high degree of similar of attribute information to the predetermined leaf node within the limits in management tree information.
0105Controlling device 20 concerning this embodiment assigns apparatus 30 comrades with the high degree of similar of attribute information to the near position in management tree information. Therefore, according to controlling device 20, data can be efficiently transmitted for the amount of information small to a plurality of apparatus 30.
0106(Extension of management tree information) Extended part 52 extends management tree information, when less than the number with which the number of the leaf nodes of the empty of management tree information was beforehand defined when new apparatus 30 was assigned to management tree information for example (for example, when an empty leaf node does not exist).
0107Extended part 52 may extend management tree information, when an empty leaf node does not exist within n degree of kinship from the leaf node of new apparatus 30 in management tree information, and apparatus 30 of the attribute information that the degree of similar is the highest. Extended part 52 is a case where a periodical or predetermined event occurs, and when there are few leaf nodes of the empty of management tree information than the number defined beforehand, it may extend management tree information. Extended part 52 may extend management tree information, whenever the number of apparatus 30 connected to the network exceeds the number defined beforehand for example.
0108Hereinafter, the transmission method of the extended example of management tree information and the node key after extension is explained.
0109Drawing 14 is a figure showing the 1st example of the management tree information before extension. For example, management tree information is the structure of a perfect binary tree of one hierarchy, as shown in Drawing 14. It is assumed that 1st apparatus 30-A is assigned to a leaf node of node number 4, and 2nd apparatus 30-B is assigned to a leaf node of node number 5. In the example of Drawing 14, 1st apparatus 30-A holds the group (device key) of two node keys K2 and K4.2nd apparatus 30-B holds the group (device key) of two node keys K2 and K5.
0110In such a case, quota part 48 cannot assign new apparatus 30 to management tree information. Then, extended part 52 adds a node to the higher rank layer of the existing route node of management tree information further, for example.
0111Drawing 15 is new in the higher rank layer of the route node in the management tree information on Drawing 14 -- it is a figure showing the example which added the what node. In the example of Drawing 15, extended part 52 adds the new route node of node number 1 to the higher rank layer of node number 2 which is the original route node, for example. Extended part 52 adds the partial tree of the perfect binary tree of one hierarchy to the lower layer of the route node of node number 1. Thereby, extended part 52 newly forms the leaf node of two empty in management tree information, and new apparatus 30 can make assignment possible.
0112Then, quota transmission section 49 assigns the new node key assigned to the extended node in management tree information to management tree information, and transmits to apparatus 30 of ending. In this case, quota transmission section 49 enciphers the new node key assigned to the extended node with the node key which is a node key to which it was assigned by the existing node, and only apparatus 30 used as the candidate for transmitting holds, and it transmits it.
0113In the example of Drawing 15, quota transmission section 49 is enciphered with node key K2 to which node key K1 assigned to the node of extended node number 1 was assigned by the node of existing node number 2, as shown in a following formula, Multicasting transmission is carried out at 1st apparatus 30-A and 2nd apparatus 30-B. C4=E (K2, K1)
0114Thereby, the 1st existing apparatus 30-A and 2nd apparatus 30-B which were assigned to management tree information before extension can hold all the node keys currently assigned by the leaf node corresponding from the route node in the management tree information after extension. In the example of Drawing 15, 1st apparatus 30-A can hold the group (device key) of three node keys K1, K2, and K4, and 2nd apparatus 30-B can hold the group (device key) of three node keys K1 and K2 and K5.
0115Thus, by extending management tree information to the higher rank layer of a route node, quota transmission section 49 can encipher the new node key assigned to the extended node in management tree information to existing apparatus 30 using the already held node key, and it can transmit it. In particular, since quota transmission section 49 may be enciphered in this case with one node key to which a new node key was assigned by the original route node, the amount of information which transmits can be lessened.
0116Drawing 16 is a figure showing the 2nd example of the management tree information before extension. For example, management tree information is the structure of a perfect binary tree of one hierarchy, as shown in Drawing 16. It is assumed that 1st apparatus 30-A is assigned to a leaf node of node number 2, and 2nd apparatus 30-B is assigned to a leaf node of node number 3. In the example of Drawing 16, 1st apparatus 30-A holds the group (device key) of two node keys K1 and K2.2nd apparatus 30-B holds the group (device key) of two node keys K1 and K3.
0117In such a case, quota part 48 cannot assign new apparatus 30 to management tree information. Then, extended part 52 may add a node to the lower layer of the existing leaf node of management tree information further, for example. And extended part 52 reassigns apparatus 30 currently assigned to the existing leaf node by which the node was added to the lower layer to a new leaf node in this case. Extended part 52 may add a node to the middle class between the existing leaf node of management tree information, and a route node further, for example.
0118Drawing 17 is a figure showing the example which newly added the node to the lower layer of the leaf node in the management tree information on Drawing 16. In the example of Drawing 17, extended part 52 adds two new leaf nodes, node number 4 and node number 5, to the lower layer of node number 2 which is the original leaf node, for example. Extended part 52 adds two new leaf nodes, node number 6 and node number 7, to the lower layer of node number 3.
0119In the example of Drawing 17, extended part 52 reassigns 1st apparatus 30-A currently assigned to node number 2 which is the original leaf node to the new leaf node of node number 4. Extended part 52 reassigns 2nd apparatus 30-B currently assigned to node number 3 which is the original leaf node to the new leaf node of node number 5. Thereby, extended part 52 newly forms the leaf node of two empty in management tree information, and new apparatus 30 can make assignment possible.
0120moreover -- a figure -- 17 -- an example -- setting -- extension -- a part -- 52 -- origin -- a leaf -- a node -- it is -- a node number -- two -- and -- a node number -- three -- a node -- being new -- a node -- a key -- K -- two -- ' -- K -- three -- ' -- assigning -- correcting.
0121Then, quota transmission section 49 is the node key to which the node key which should newly be held was assigned by the existing node, it enciphers with the node key which only apparatus 30 used as the candidate for transmitting holds, and is assigned to management tree information, and transmits to apparatus 30 of ending. In the example of Drawing 17, as shown in a following formula, quota transmission section 49 enciphers new node key K2' and K4 with node key K2 to which it was assigned by the node of existing node number 2, and transmits to 1st apparatus 30-A. Only 1st apparatus 30-A that is a candidate for transmitting holds node key K2, and 2nd apparatus 30-B does not hold it. Thereby, 1st apparatus 30-A can hold three node keys K1, K2', and the group (device key) of K4. C5=E (K2, K2') C6=E (K2, K4)
0122In the example of Drawing 17, as shown in a following formula, quota transmission section 49 enciphers new node key K2' and K5 with node key K3 to which it was assigned by the node of existing node number 3, and transmits to 2nd apparatus 30-B. Only 2nd apparatus 30-B that is a candidate for transmitting holds node key K3, and 1st apparatus 30-A does not hold it. Thereby, 2nd apparatus 30-B can hold the group (device key) of three node keys K1, K2', and K5. C7=E (K3, K2') C8=E (K3, K5)
0123Thus, by extending management tree information to the lower layer of a leaf node, quota transmission section 49 can encipher the new node key assigned to the extended node in management tree information to existing apparatus 30 using the already held node key, and it can transmit it. Extended part 52 is good also as K2'=K2. Thereby, since quota transmission section 49 does not need to transmit node key K2 to 1st apparatus 30-A, it can further reduce the amount of information which transmits.
0124Drawing 18 is a figure showing the example which newly added the node to the layer between the route node and leaf node in the management tree information on Drawing 16. Extended part 52 may add a still newer node to the layer between the route node of management tree information, and a leaf node, for example.
0125In the example of Drawing 18, extended part 52 newly adds the node of node number 4 to the lower layer of the route node of node number 1, for example. And extended part 52 connects the leaf node of node number 2, and the leaf node of node number 3 to the lower layer of the node of node number 4. Extended part 52 adds the partial tree of the perfect binary tree of one hierarchy to the lower layer of the route node of node number 1. Thereby, extended part 52 newly forms the leaf node of two empty in management tree information, and new apparatus 30 can make assignment possible.
0126Then, quota transmission section 49 assigns the node key assigned to the node of added node number 4 to management tree information, and transmits to 1st apparatus 30-A of ending, and 2nd apparatus 30-B. Node key K2 to which new node key K4 was assigned by the node of existing node number 2 as for quota transmission section 49 in the example of Drawing 18 as shown in a following formula, and node key K3 assigned to the node of existing node number 3, It enciphers, respectively and carries out multicasting transmission at 1st apparatus 30-A and 2nd apparatus 30-B. Thereby, 1st apparatus 30-A can hold the group (device key) of three node keys K1, K2, and K4.2nd apparatus 30-B can hold the group of three node keys K1, K3, and K4. C9=E (K2, K4) C10=E (K3, K4)
0127Thus, by adding a still newer node to the layer between the route node of management tree information, and a leaf node, quota transmission section 49 can encipher the node key assigned to the added new node with the node key to which it was assigned by the existing node, and it can transmit it. Thereby, according to quota transmission section 49, the amount of information which transmits can be lessened.
0128As shown in a following formula, it may encipher with node key K1 to which new node key K4 was assigned by the node of existing node number 1, and quota transmission section 49 may be constituted so that multicasting transmission may be carried out at 1st apparatus 30-A and 2nd apparatus 30-B. Even if constituted in this way, 1st apparatus 30-A can hold the group (device key) of three node keys K1, K2, and K4.2nd apparatus 30-B can hold the group (device key) of three node keys K1, K3, and K4. Thereby, since quota transmission section 49 should just transmit one cryptogram, it can further reduce the amount of information which transmits. C11=E (K1, K4)
0129Drawing 19 is a figure showing the example in the management tree information on Drawing 16 in which while added a new node to the lower layer of the leaf node. Extended part 52 may add a node to the lower layer of any one leaf node of the existing of management tree information further, for example. And extended part 52 reassigns apparatus 30 currently assigned to the existing leaf node by which the node was added to the lower layer to a new leaf node in this case.
0130In the example of Drawing 19, extended part 52 adds two new leaf nodes, node number 4 and node number 5, to the lower layer of node number 3 which is the original leaf node, for example. In the example of Drawing 19, extended part 52 reassigns 2nd apparatus 30-B currently assigned to node number 3 which is the original leaf node to the new leaf node of node number 4. Thereby, extended part 52 newly forms the leaf node of one empty in management tree information, and new apparatus 30 can make assignment possible. In the example which is Drawing 19, extended part 52 reassigns new node key K3' to the node of node number 3 which is the original leaf node.
0131Then, quota transmission section 49 transmits the node key which should newly be held to 2nd apparatus 30-B that changed the quota position. In the example of Drawing 19, as shown in a following formula, quota transmission section 49 enciphers new node key K3' and K4 with node key K3 to which it was assigned by the node of existing node number 3, and transmits to 2nd apparatus 30-B. Thereby, 2nd apparatus 30-B can hold three node keys K1, K3', and the group (device key) of K4. C12=E (K3, K3') C13=E (K3, K4)
0132Thus, by extending management tree information to the lower layer of one leaf node, quota transmission section 49 can encipher the new node key assigned to the extended node in management tree information to existing apparatus 30 using the already held node key, and it can transmit it. Extended part 52 is good also as K3'=K3. Thereby, since quota transmission section 49 does not need to transmit node key K3 to 2nd apparatus 30-B, it can lessen the amount of information which transmits.
0133Drawing 20 is a figure showing the example which newly added the node to the layer between the route node and one leaf node in the management tree information on Drawing 16. Extended part 52 may add a still newer node to the layer between the route node of management tree information, and one leaf node, for example.
0134In the example of Drawing 20, extended part 52 newly adds the node of node number 4, for example between the route node of node number 1, and the leaf node of node number 3. And extended part 52 adds the new leaf node of node number 5 to the lower layer of the node of node number 4. Thereby, extended part 52 newly forms the leaf node of one empty in management tree information, and new apparatus 30 can make assignment possible.
0135Then, quota transmission section 49 assigns the node key assigned to the node of added node number 4 to management tree information, and transmits to 2nd apparatus 30-B of ending. In the example of Drawing 20, it enciphers with node key K3 to which new node key K4 was assigned by the node of existing node number 3, and quota transmission section 49 transmits to 2nd apparatus 30-B, as shown in a following formula. Thereby, 2nd apparatus 30-B can hold the group (device key) of node keys K1, K3, and K4 of three devices. C14=E (K3, K4)
0136Thus, by adding a still newer node to the layer between the route node of management tree information, and a leaf node, quota transmission section 49 can encipher the node key assigned to the added new node with the node key to which it was assigned by the existing node, and it can transmit it. Thereby, according to quota transmission section 49, the amount of information which transmits can be lessened.
0137(Reconstruction of management tree information) Below, the reconfiguration method of management tree information and the transmission method of the node key after reconstruction are explained. Reconstruction section 53 changes the quota position to the leaf node of apparatus 30 in management tree information so that apparatus 30 comrades with the high degree of similar may concentrate on the range of a near node and may be arranged.
0138Reconstruction section 53 performs reconstruction, when the event defined periodically or beforehand occurs for example. For example, reconstruction section 53 may reconstruct management tree information, after management tree information is extended by extended part 52. For example, from the leaf node of new apparatus 30 in management tree information, and apparatus 30 of the attribute information that the degree of similar is the highest, reconstruction section 53 may reconstruct management tree information, when an empty leaf node does not exist within n degree of kinship. For example, from the leaf node of new apparatus 30 in management tree information, and apparatus 30 of the attribute information that the degree of similar is the highest, reconstruction section 53 may be a case where an empty leaf node exists within n degree of kinship, or may reconstruct management tree information.
0139Hereinafter, the example which reconstructs management tree information is explained, using the element information which changes according to progress of the time contained in attribute information as an index of the degree of similar.
0140Drawing 21 is a figure showing the management tree information before reconstruction. In an example of Drawing 21, management tree information before reconstruction is the structure of a perfect binary tree of two hierarchies. It is assumed that 1st apparatus 30-A is assigned to a leaf node of node number 4, 2nd apparatus 30-B is assigned to a leaf node of node number 5, and 3rd apparatus 30-C is assigned to a leaf node of node number 6. In the example of Drawing 21, 1st apparatus 30-A holds the group (device key) of three node keys K1, K2, and K4.2nd apparatus 30-B holds the group (device key) of three node keys K1 and K2 and K5.3rd apparatus 30-C holds the group (device key) of three node keys K1, K3, and K6.
0141Attribute acquiring part 46 acquires attribute information from each apparatus 30. The average consumption electric power of 1st apparatus 30-A presupposes that the average consumption electric power of 1000 [W] and 2nd apparatus 30-B was [the average consumption electric power of 100 [W] and 3rd apparatus 30-C] 1200 [W]. In this case, since the difference of average consumption electric power is small and the degree of similar is high, 1st apparatus 30-A and 3rd apparatus 30-C have a high possibility of, for example, receiving simultaneously the control commands which direct control of power consumption.
0142When making 1st apparatus 30-A and 3rd apparatus 30-C execute control commands, first, controlling device 20 generates the cryptogram shown with a following formula, and transmits. Thereby, 1st apparatus 30-A and 3rd apparatus 30-C can hold group key GK. Since 2nd apparatus 30-B does not hold node keys K4 and K6, it cannot acquire group key GK. C15=E (K4, GK) C16=E (K6, GK)
0143Then, as shown in a following formula, controlling device 20 enciphers control commands CMD by group key GK, and carries out multicasting transmission at 1st apparatus 30-A and 3rd apparatus 30-C. C17=E (GK, CMD)
01441st apparatus 30-A and 3rd apparatus 30-C decode the received cryptogram by group key GK, and execute control commands CMD. Thus, as management tree information is shown in Drawing 21, when it is constituted, controlling device 20 must generate three cryptograms, in order to transmit control commands to 1st apparatus 30-A and 3rd apparatus 30-C.
0145Drawing 22 is a figure showing the management tree information after reconstruction. As for reconstruction section 53, the average consumption electric power of the attribute information reconstructs management tree information, for example so that apparatus 30 comrades beyond a steady value may be arranged in the neighborhood. For example, as for reconstruction section 53, average consumption electric power reconstructs management tree information so that apparatus 30 more than 1000 [W] may be arranged less than at the relation in the 2nd degree. Therefore, as shown in Drawing 22, reconstruction section 53 assigns 1st apparatus 30-A to the leaf node of node number 4, assigns 3rd apparatus 30-C to the leaf node of node number 5, and assigns 2nd apparatus 30-B to the leaf node of node number 6.
0146Reconstruction section 53 changes the node key assigned to each node with change of assignment of apparatus 30. In this case, reconstruction section 53 does not need to change the node key which apparatus 30 in which a quota change was made held, and does not need to change the node key which apparatus 30 in which a quota change was made does not hold. Reconstruction section 53 does not need to change the node key which all the apparatus 30 in which a quota change was made held in common, either. In the example of Drawing 22, reconstruction section 53 changes the node key of the node of node number 2, the node of node number 3, the node of node number 5, and the node of node number 6.
0147And quota transmission section 49 transmits the changed node key to apparatus 30. In the example of Drawing 22, as shown in the following formula, quota transmission section 49 enciphers node key K2' with node key K4, and transmits to 1st apparatus 30-A. Thereby, 1st apparatus 30-A can hold three node keys K1, K2', and the group (device key) of K4. C18=E (K4, K2')
0148As shown in the following formula, quota transmission section 49 enciphers node key K2' and K5' with node key K6, and transmits to 3rd apparatus 30-C. Thereby, 3rd apparatus 30-C can hold the group (device key) of three node keys K1, K2', and K5'. C19=E (K6, K2') C20=E (K6, K5')
0149As shown in the following formula, quota transmission section 49 enciphers node key K3' and K6' by node key K5, and transmits to 2nd apparatus 30-B. Thereby, 2nd apparatus 30-B can hold the group (device key) of three node keys K1, K3', and K6'. C21=E (K5, K3') C22=E (K5, K6')
0150Then, when making 1st apparatus 30-A and 3rd apparatus 30-C execute control commands, first, controlling device 20 generates the cryptogram shown with a following formula, and carries out multicasting transmission at 1st apparatus 30-A and 3rd apparatus 30-C. Thereby, 1st apparatus 30-A and 3rd apparatus 30-C can hold group key GK. C21=E (K2', GK)
0151Then, as shown in a following formula, controlling device 20 enciphers control commands CMD by group key GK, and carries out multicasting transmission at 1st apparatus 30-A and 3rd apparatus 30-C. C22=E (GK, CMD)
0152That is, as shown management tree information in Drawing 22, when it is reconstructed, controlling device 20 should just transmit two cryptograms in order to make 1st apparatus 30-A and 3rd apparatus 30-C execute control commands. Therefore, controlling device 20 can reduce the one number of the cryptograms which must transmit in order to make 1st apparatus 30-A and 3rd apparatus 30-C execute control commands.
0153Between 1st apparatus 30-A and 3rd apparatus 30-C, without sharing group key GK, controlling device 20 may encipher control commands CMD by node key K2', and may carry out multicasting transmission. In this case, controlling device 20 can transmit control commands to 1st apparatus 30-A and 3rd apparatus 30-C by one cryptogram.
0154As mentioned above, by reconstructing management tree information so that a possibility that multicasting transmission of the control commands will be carried out may be settled in a small number of partial tree in high apparatus 30, controlling device 20 can reduce the number of the cryptograms which should transmit, and can reduce the amount of information at the time of transmission.
0155Although average consumption electric power was used for reconstruction section 53 as an index of the degree of similar at the time of reconstructing management tree information, it is good also considering the element information on attribute information not only without this but time change as an index of the degree of similar. Reconstruction section 53 is good also considering the value which compounded the element information on a plurality of kinds as an index of the degree of similar. Reconstruction section 53 is good also considering the degree of similar which changed and compounded dignity attachment according to element information as an index.
0156Controlling device 20 applied to this embodiment as mentioned above reconstructs management tree information so that apparatus 30 with a high possibility that multicasting transmission of the control commands will be carried out may be settled in the partial tree in which a small number of node is constituted. Thereby, according to controlling device 20, the amount of communications for sharing the group key or node key used for encryption or attestation is reducible. Controlling device 20 can extend management tree information according to the increase in apparatus 30. Therefore, controlling device 20 can make management tree information small, when there is few apparatus 30, and it can reduce the amount of memories, etc.
0157Drawing 23 is a figure showing an example of the hardware constitutions of controlling device 20 concerning an embodiment. Controlling device 20 concerning this embodiment is realized by the information processor of hardware constitutions as shown, for example in Drawing 23. Apparatus 30 is also realized by controlling device 20 and the information processor of the same hardware constitutions.
0158This information processor is with CPU (Central Processing Unit) 201, It has RAM (Random Access Memory) 202, ROM (Read Only Memory) 203, operation input device 204, display 205, memory storage 206, and communication apparatus 207. And these each part is connected by bus.
0159CPU201 is a processor which performs operation processing, control processing, etc. according to a program. CPU201 performs various processings by making the predetermined field of RAM202 into workspace by collaboration with the program memorized by ROM203 and memory storage 206 grade.
0160RAM202 are memories, such as SDRAM (Synchronous Dynamic Random Access Memory). RAM202 functions as workspace of CPU201. ROM203 is a memory which rewrites a program and a variety of information and it memorizes impossible.
0161Operation input devices 204 are input devices, such as a mouse and a keyboard. Operation input device 204 receives the information in which the operation input was done by the user as an indication signal, and outputs an indication signal to CPU201.
0162Displays 205 are display devices, such as LCD (Liquid Crystal Display). Display 205 displays a variety of information based on the display signal from CPU201.
0163Memory storage 206 is a storage with semiconductors, such as a flash memory, or a device which carries out writing and read-out for data to a recordable storage etc. magnetically or optically. Memory storage 206 carries out writing and read-out of data to a storage according to the control from CPU201. Communication apparatus 207 communicates via external apparatus and a network according to the control from CPU201.
0164A program run with controlling device 20 of this embodiment, An apparatus discovery module, an apparatus attestation module, an attribute acquisition module, the degree calculation module of similar, It has module composition containing a quota module, a quota transmitting module, a group key transmitting module, a generation module, an enhancement module, a reconstruction module, an encryption module, and the 1st communication module. This program is developed on RAM202 by CPU201 (processor), and it performs, An information processor is operated as apparatus finding part 44, apparatus authentication section 45, attribute acquiring part 46, similarity calculating part 47, quota part 48, quota transmission section 49, group key transmission section 50, generation part 51, extended part 52, reconstruction section 53, encryption section 54, and the 1st communications department 55.
0165Such [controlling device 20] composition not onlyEven if there are little apparatus finding part 44, apparatus authentication section 45, attribute acquiring part 46, similarity calculating part 47, quota part 48, quota transmission section 49, group key transmission section 50, generation part 51, extended part 52, reconstruction section 53, encryption section 54, and 1st communications department 55It may be the composition that hardware circuitry (for example, integrated circuit) realized the part.
0166A program run by apparatus 30 of this embodiment, It has module composition containing an attribute measurement module, a controlling device discovery module, a demand module, a controlling device attestation module, an attribute transmitting module, a quota receiving module, a group key receiving module, a decoding module, and the 2nd communication module. This program is developed on RAM202 by CPU201 (processor), and it performs, An information processor is operated as attribute measurement part 63, controlling device finding part 64, demand part 65, controlling device authentication section 66, attribute transmission section 67, quota receiving part 68, group key receiving part 69, decoding part 70, and the 2nd communications department 71.
0167not only composition such [apparatus 30] but attribute measurement part 63, controlling device finding part 64, demand part 65, controlling device authentication section 66, attribute transmission section 67, quota receiving part 68, group key receiving part 69, and decoding part 70 -- andIt may be the composition that hardware circuitry (for example, integrated circuit) realized at least one copy of the 2nd communications department 71.
0168A program run with controlling device 20 of this embodiment, By the file of form or the form which can be performed installable in a computer, by computers, such as CD-ROM, a flexible disk, CD-R, and DVD (Digital Versatile Disk), it is recorded on the recording medium which can be read and is provided.
0169The program run with controlling device 20 of this embodiment may be stored on the computer connected to networks, such as the Internet, and it may constitute so that it may provide by making it download via a network. It may constitute so that the program run with controlling device 20 of this embodiment may be provided or distributed via networks, such as the Internet. It may constitute so that the program run with controlling device 20 may be beforehand included in ROM etc. and may be provided.
0170Although some embodiments of the present invention were described, these embodiments are shown as an example and limiting the scope of an invention does not have intention of them. These new embodiments can be carried out with other various forms, are the ranges which do not deviate from the gist of an invention, and various abbreviations and replacement are performed and they can make a change. These embodiments and the modification of those are included in the invention indicated in the range of a claim, and its equivalent range while they are included in the range and gist of an invention.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| JP2020129808A | Cited by | Japan | – | Search report | – |
| JP2018157246A | Cited by | Japan | – | Search report | – |
| WO02060116A2 | Cites | World Intellectual Property Organization (WIPO) | A | International search | 1-20 |
| WO02080448A1 | Cites | World Intellectual Property Organization (WIPO) | YA | International search | 12-19 |
| JP2003204321A | Cites | Japan | A | International search | 1-20 |
| JP2005198116A | Cites | Japan | YA | International search | 12-19 |
| WO2014010087A1 | Cites | World Intellectual Property Organization (WIPO) | A | International search | 1-20 |
| US6049878A | Cites | United States of America | A | International search | 1-20 |
5 members in 3 offices
Members5
| Document | Office | Kind | |
|---|---|---|---|
| WO2016147303A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| JPWO2016147303A1 | Japan | A1 | |
| US2017180120A1 | United States of America | A1 | |
| JP6271808B2 | Japan | B2 | |
| US10447469B2 | United States of America | B2 |
Numbers
- Publication
- 2016/147303
- Application
- 57749
Titles5
- English
- A controlling device, a program, a system, apparatus, and a method
- French
- APPAREIL, SYSTÈME, PROGRAMME, DISPOSITIF DE GESTION ET PROCÉDÉ
- Japanese
- 管理装置、プログラム、システム、機器および方法
- Unlabeled
- 管理装置、プログラム、システム、機器および方法
- Japanese
- A controlling device, a program, a system, apparatus, and a method
Classification
- CPC, 3
- H04L9/0836
- H04L9/0819
- H04L63/065
- IPC, 1
- H04L9 08
Designated states147
- Regional, 80
- Botswana
- Ghana
- Gambia
- Kenya
- Liberia
- Lesotho
- Malawi
- Mozambique
- Namibia
- Rwanda
- Sudan
- Sierra Leone
- Eswatini
- United Republic of Tanzania
- Uganda
- Zambia
- Zimbabwe
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Russian Federation
- Tajikistan
and 56 moreShow fewer
- Turkmenistan
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Lithuania
- Luxembourg
- Latvia
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Equatorial Guinea
- Guinea-Bissau
- Comoros
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- Sao Tome and Principe
- National, 67
- United Arab Emirates
- Antigua and Barbuda
- Angola
- Australia
- Bosnia and Herzegovina
- Barbados
- Bahrain
- Brunei Darussalam
- Brazil
- Belize
- Canada
- Chile
- China
- Colombia
- Costa Rica
- Cuba
- Dominica
- Dominican Republic
- Algeria
- Ecuador
- Egypt
- Grenada
- Georgia
- Guatemala
and 43 moreShow fewer
- Honduras
- Indonesia
- Israel
- India
- Iran (Islamic Republic of)
- Japan
- Saint Kitts and Nevis
- Democratic People’s Republic of Korea
- Republic of Korea
- Lao People’s Democratic Republic
- Saint Lucia
- Sri Lanka
- Libya
- Morocco
- Republic of Moldova
- Montenegro
- Madagascar
- Mongolia
- Mexico
- Malaysia
- Nigeria
- Nicaragua
- New Zealand
- Oman
- Panama
- Peru
- Papua New Guinea
- Philippines
- Qatar
- Saudi Arabia
- Seychelles
- Singapore
- El Salvador
- Syrian Arab Republic
- Thailand
- Tunisia
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Saint Vincent and the Grenadines
- Viet Nam
- South Africa